Impact
Vulnerability in the Installation component of Oracle Sie attacker who has logged onto the underlying infrastructure to compromise the deployment. The flaw enables the attacker to take over the Siebel CRM Deployment process, giving full control over the system. The impact includes complete loss of confidentiality, integrity, and availability of the deployment, and the attacker can potentially extend influence to other parts of the Siebel environment.
Affected Systems
Oracle Siebel CRM Deployment product is affected, specifically versions 17.0 through 26.7. The vulnerability is present across all builds within this range, as identified by the Oracle CNA.
Risk and Exploitability
The CVSS base score of 7.8 indicates high severity. The EPSS score of less than 1% shows a very low exploitation probability in the current threat landscape, and the vulnerability is not listed in the CISA KEV catalog. The likely attack scenario requires the attacker to have low-privilege access to the server hosting the deployment; from there, the attacker can execute the installation component exploit and achieve a full takeover. No network-level attack vector is documented, so the flaw is considered local.
OpenCVE Enrichment